Skip to content

Legal

Security

You're putting us in front of your customers and giving us recordings of the conversations. Here's what we do to deserve that. Anything unclear — [email protected].

Encryption

  • TLS 1.3 for all data in transit
  • AES-256 encryption for data at rest
  • End-to-end encryption for sensitive communications
  • Secure key management system

Access control

  • Multi-factor authentication (MFA)
  • Role-based access control (RBAC)
  • Regular access reviews
  • Audit logging of all access attempts

Infrastructure

  • Regular security audits and penetration testing
  • DDoS protection and mitigation
  • Automated threat detection
  • Tenant isolation across every workspace

Incident response

  • Incident response team available 24/7
  • Documented incident response procedures
  • Regular security drills and tabletop exercises
  • Transparent security incident reporting

What we do with your call data

We don't train on your calls

Your recordings, transcripts, and contact data are used to deliver your service. They aren't used to train models, ours or anyone else's.

Your data is exportable

Calls, transcripts, recordings, and contacts are available through the API. If you leave, you take everything with you.

Tenant isolation

Every workspace is scoped to its own account. Data is not shared, pooled, or aggregated across customers.

Subprocessors

We use third parties for telephony, speech, and infrastructure. Which ones depends on how your agents are configured — ask and we'll give you the current list in writing.

Questions we get from security reviews

Do you have SOC 2 / ISO 27001?

Ask us for our current compliance status rather than relying on a badge on a marketing page. We'd rather tell you exactly where we are — including what we don't have yet — than imply something we can't evidence.

Where is data stored?

It depends on your configuration and the providers your agents use. If you have a data residency requirement, raise it before you build — it's much easier to answer up front than to retrofit.

Can we get a DPA?

Yes. Email [email protected] and we'll get one to you.

How do we report a vulnerability?

Email [email protected] with enough detail to reproduce it. We'll acknowledge it, and we won't take legal action against good-faith research that doesn't degrade the service or touch other customers' data.

Are calls recorded, and is that legal?

Recording is configurable, and consent capture runs on the call path where it's required. Recording law varies by jurisdiction and by who's on the call — the platform gives you the controls, but the obligation to use them correctly is yours.

Reporting a vulnerability

Send it to [email protected] with enough detail to reproduce. We'll acknowledge it and keep you posted on the fix. We won't pursue good-faith research that avoids degrading the service and doesn't touch other customers' data.